Chrome 154 Patches 108 Vulnerabilities
Google on Tuesday announced the release of Chrome 154 to the stable channel with patches for 108 vulnerabilities, including 11 critical-severity bugs.
The critical security defects include buffer overflows (three in ANGLE and one in WebGL), out-of-bounds writes (two in GPU and one in WebGL), and use-after-free bugs in ServiceWorker, Fullscreen, WindowDialog, and AdFilter.
Nine of the critical issues were reported by external researchers. In total, 32 of the newly patched flaws were reported externally, while the rest were discovered by Google.
Google says it handed out $18,000 in bug bounty rewards to the reporting researchers, but the final amount could be much higher, as the company has yet to determine the amounts to be paid for most of the externally reported bugs.
Twenty-five of the remaining vulnerabilities are high-severity bugs, including a dozen use-after-free defects and multiple type confusion, uninitialized resource, and buffer overflow issues.
High-severity missing authorization, UI...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE